LotsTeam connects your AI agent through OAuth, and the agent works with the permissions of the person who signed in: it can do only what that person's role allows, one action at a time, and it has no delete tools. It can't create projects, invite people or change roles, because those stay in the dashboard. It sends a reply to a customer or publishes a changelog entry only when you tell it to, and the "it shipped" email to people who asked is an opt-in on each entry.
This page explains how sign-in works, what each role can do, what your agent can and can't do, and how to give an agent less access than you have. It comes from LotsTeam's documentation and product code, which I read on 8 October 2026. In LotsTeam a "post" means a piece of product feedback, such as a request, a bug or an idea.
How your agent signs in
- MCP: OAuth in your browser. You add
https://api.lots.team/mcpto ChatGPT, Claude or another MCP client and sign in with the email you use for LotsTeam. No key is pasted into the chat. The flow is OAuth 2.1 with PKCE, and the server has a registration endpoint so your client can register itself. - Tokens are stored as hashes. LotsTeam keeps a hash of each access token with its expiry, not the token itself, and it rejects tokens that are expired or revoked. The default scope is
mcp:execute. - REST: an API key. For scripts, you create a key in the dashboard. It's shown once, goes in an
Authorization: BearerorX-API-Keyheader, and is limited to 100 requests a minute per key. LotsTeam stores a hash of the key.
The agent never has more than a person's access. It acts as the person who signed in, so its writes are that person's writes.
What each role can do
LotsTeam checks the role and the specific permission on every action the agent takes, such as creating a task, creating a changelog entry or replying to a message.
| Role | Projects | What it can do |
|---|---|---|
| Owner | All projects | Everything, including billing and members |
| Admin | All projects | Almost everything, except managing billing and deleting the organization |
| Member | Only the projects they're assigned to | The permissions they were given, from a template or set by hand |
| Viewer | All projects | Read posts, tasks and the changelog, and comment on posts. A viewer can't read support messages, and can't create, edit or publish |
Members can be given a built-in template or custom permissions. One built-in template, "Intern", is deliberately narrow. It can view and create posts and comment on them, view, create, edit and complete tasks, and view the changelog. It can't edit or change the status of posts, assign tasks, delete anything, create or publish changelog entries, or read or reply to support messages, and it can't change settings.
What the agent does only when you say so
| Action | What has to happen first |
|---|---|
| Reply to a support message | You tell it to send. The reply is stored on the thread and emailed to the customer, so the agent shows you the draft first |
| Publish a changelog entry | You ask it to publish. A new entry is a draft until then |
| Email the people who asked | Opt-in on each entry. It happens once per entry, goes to the authors of the posts linked to the task, honours a per-project opt-out, and every email has an unsubscribe link. A single entry emails at most 100 people. Anonymous voters have no email address, so they aren't emailed |
| Show a task on the public roadmap | A task is public only when it's deliberately flagged public, so check before you share the portal |
What the agent can't do at all
- Dashboard-only work. Creating projects, inviting members, changing roles, branding, custom domains, the widget and billing. The agent can't do these, and it tells you to use the dashboard.
- Delete. LotsTeam's MCP server has 26 tools, and none of them deletes anything. The agent can create, read and update posts and tasks, comment, link a post to a task, read and reply to support threads, and draft and publish changelog entries.
- Act outside its projects. A member's agent reads and changes only the projects that member is assigned to.
- Build the feature. A task marked done isn't proof that code shipped, and LotsTeam doesn't write your code.
How to give an agent less access than you have
Because the agent acts as whoever signed in, the way to limit it is to sign it in as someone with a narrower role:
- In the dashboard, invite a teammate account for your agent, for example an address you control.
- Give it the role that fits the job: Viewer for read-only triage, a Member with the Intern template for logging posts and updating tasks, or a custom permission set.
- Assign it only the projects it needs.
- Connect your agent to LotsTeam with that account instead of yours.
If you want an agent to read support threads and draft replies, but never send them, give it permission to view messages without permission to reply, and have it hand the draft to you. The tool checks the reply permission when it tries to send.
How data is protected in the database
The public database key that ships in every page and in the feedback widget has no table privileges: every LotsTeam table denies it. Pages and the API read and write through server code that checks the permission first, and a script verifies the grants and row-level security state, not just whether a table returns a row. The project also runs a production dependency audit in its CI pipeline.
Run your product feedback from your agent
Give your agent this and let it set itself up:
Read https://lots.team/skill.md and help me connect LotsTeam for you.
LotsTeam costs $9 per project a month, or plans from $24 for 3 projects, with unlimited team members, the MCP server and the REST API on every plan. New accounts get 10,000 free credits, valid 90 days, no card. See pricing. To compare how other feedback tools handle agent access, read The Best Feedback Tools With MCP Support.
Common questions
Is LotsTeam safe to connect to ChatGPT or Claude?
LotsTeam signs your agent in with OAuth, so you don't paste a key into the chat, and the agent has only the permissions of the person who signed in. It has no delete tools, and it can't create projects, invite people or change roles.
Can the agent delete my posts, tasks or changelog?
No. None of the 26 MCP tools deletes anything. Deleting happens in the dashboard, by a person with the right permission.
Can my agent email my customers without asking me?
Not on its own instructions. A support reply is sent only when you tell the agent to send it, and "it shipped" emails go out only when you opt in on that changelog entry. Each of those emails has an unsubscribe link.
What can a viewer see?
A viewer can read posts, tasks and the changelog across all projects, and comment on posts. A viewer can't read support messages and can't create, edit or publish anything.
How do I stop an agent from touching one project?
Sign the agent in as a Member and assign only the projects it should use. A member's agent can't read or change any project it isn't assigned to.
Where are my agent's access tokens stored?
LotsTeam stores a hash of each OAuth access token and API key, not the token itself, and rejects tokens that are expired or revoked.
Details from LotsTeam's documentation and product code, read on 8 October 2026: lots.team/skill.md, the tool reference, the REST documentation and lots.team/pricing. Features and permissions can change; check those pages for the latest.